K2 Comment Vulnerability

Questions related to the configuration of Joomla, Templates, and Security related questions/issues
Rate this topic: Evaluations: 0, 0.00 on the average.Evaluations: 0, 0.00 on the average.Evaluations: 0, 0.00 on the average.Evaluations: 0, 0.00 on the average.Evaluations: 0, 0.00 on the average.Evaluations: 0, 0.00 on the average.
GK User
Mon Nov 10, 2014 7:36 am
Hello,

I understand K2 is very much used by Gavick Pro, but for now, I stick more to the basic but very versatile Joomla modules created by Gavick. Thus, usually I unpublished most of the K2 modules, and trash all the demo K2 articles (which now comprise most of the demo articles in the templates).

What happened though is that the K2 comment is very vulnerable, and has been saddled with spam in one site, even if it was unpublished from the beginning. I trashed all the K2 articles after installation. When I dropped the k2 comment module, it destroyed the site. And worked only after it was replaced taken from a clean source. But, once restored, in just a few hours, more than a million comments built up again. Trashing all the K2 modules and some undetected K2 articles did not help either. Comments build up in the database quite fast.

Fortunately, not all the sites are affected. I will install some anti-spam and possibly CAPCHA extensions, but for now, I would rather not have K2 modules in my sites

So, through the phpMyAdmin, how do I remove most if not all of the K2 modules (in the database tables) without destroying the site?

Cornelio
User avatar
Expert Boarder

GK User
Mon Nov 10, 2014 7:40 am
I think it would be better to ask on k2 support forum.
We are not specialists if it goes to the code of K2, we only make styling for the plugin.
User avatar
Moderator

GK User
Mon Nov 10, 2014 7:53 am
Hi Cyberek,

I might get a hostile reception if I say not so very nice things about their most beloved creation. I really do not want to understand K2 for now,. Maybe in the future when I have time???

What I am requesting actually is how to get rid of all the K2 modules in the database tables without destroying the site. It seems unpublishing or trashing would not suffice. I have to remove it in the database itself via the phpMyAdmin. How could that be done without breaking the site?

How do I make sure the trash is empty by the way? I can find a way to find out if it is empty.

Cornelio

Cyberek wrote:I think it would be better to ask on k2 support forum.
We are not specialists if it goes to the code of K2, we only make styling for the plugin.
User avatar
Expert Boarder

GK User
Tue Nov 11, 2014 9:02 am
I think you only need to uninstall those modules. Even if they leave something in the database, it should do no harm.
User avatar
Moderator


cron